CLI reference for Satellite commands

Refer to these Satellite CLI commands when you want to automate the creation and management of your Satellite location, including location, host, cluster, and endpoint operations.

To install the CLI, see Installing the the CLI. To view a high-level map of all the IBM Cloud Satellite commands, see the CLI map.

  1. Install the IBM Cloud CLI. See Getting started with the IBM Cloud CLI.

  2. Install the ks plug-in.

    ibmcloud plugin install ks
    

Acl commands

View and manage Satellite access control lists (ACLs).

ibmcloud sat acl create

Satellite

Create an ACL.

ibmcloud sat acl create --name NAME --subnet SUBNET [--subnet SUBNET ...] [--endpoint ENDPOINT ...] [-q] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--endpoint
A name or ID of an endpoint to enable for this ACL.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--name
The name for the ACL.
-q
Do not show the message of the day or update reminders.
--subnet
An IP or CIDR block allowed by this ACL. Value must be fully contained in the following CIDRs: 10.0.0.0/8, 161.26.0.0/16, 166.8.0.0/14, 172.16.0.0/12.

Examples

Create an ACL

ibmcloud sat acl create --name NAME --subnet SUBNET --connector-id ID

ibmcloud sat acl endpoint add

Satellite

Add one or more enabled endpoints to an ACL.

ibmcloud sat acl endpoint add --acl-id ID --endpoint ENDPOINT [--endpoint ENDPOINT ...] [-q] (--connector-id ID | --location LOCATION)

Command options

--acl-id
Specify the ID of the ACL. To list all ACLs, run ibmcloud sat acl ls.
--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--endpoint
A name or ID of an endpoint to enable for this ACL.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.

Examples

Add one or more enabled endpoints to an ACL

ibmcloud sat acl endpoint add --acl-id ID --endpoint ENDPOINT --connector-id ID

ibmcloud sat acl endpoint help

Show help

ibmcloud sat acl endpoint help

Examples

Show help

ibmcloud sat acl endpoint help

ibmcloud sat acl endpoint ls

Satellite

List all enabled endpoints for an ACL.

ibmcloud sat acl endpoint ls --acl-id ID [--output OUTPUT] [-q] (--connector-id ID | --location LOCATION)

Command options

--acl-id
Specify the ID of the ACL. To list all ACLs, run ibmcloud sat acl ls.
--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all enabled endpoints for an ACL

ibmcloud sat acl endpoint ls --acl-id ID --connector-id ID

ibmcloud sat acl endpoint rm

Satellite

Remove one or more enabled endpoints from an ACL.

ibmcloud sat acl endpoint rm --acl-id ID --endpoint ENDPOINT [--endpoint ENDPOINT ...] [-q] (--connector-id ID | --location LOCATION)

Command options

--acl-id
Specify the ID of the ACL. To list all ACLs, run ibmcloud sat acl ls.
--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--endpoint
A name or ID of an endpoint to disable for this ACL.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.

Examples

Remove one or more enabled endpoints from an ACL

ibmcloud sat acl endpoint rm --acl-id ID --endpoint ENDPOINT --connector-id ID

ibmcloud sat acl get

Satellite

View the details of an ACL.

ibmcloud sat acl get --acl-id ID [--output OUTPUT] [-q] (--connector-id ID | --location LOCATION)

Command options

--acl-id
Specify the ID of the ACL. To list all ACLs, run ibmcloud sat acl ls.
--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

View the details of an ACL

ibmcloud sat acl get --acl-id ID --connector-id ID

ibmcloud sat acl help

Show help

ibmcloud sat acl help

Examples

Show help

ibmcloud sat acl help

ibmcloud sat acl ls

Satellite

List all ACLs for a Satellite connector or location.

ibmcloud sat acl ls [--output OUTPUT] [-q] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all ACLs for a Satellite connector or location

ibmcloud sat acl ls --connector-id ID

ibmcloud sat acl rm

Satellite

Delete an ACL.

ibmcloud sat acl rm --acl-id ID [-q] (--connector-id ID | --location LOCATION)

Command options

--acl-id
Specify the ID of the ACL. To list all ACLs, run ibmcloud sat acl ls.
--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.

Examples

Delete an ACL

ibmcloud sat acl rm --acl-id ID --connector-id ID

ibmcloud sat acl subnet add

Satellite

Add one or more subnets to an ACL.

ibmcloud sat acl subnet add --acl-id ID --subnet SUBNET [--subnet SUBNET ...] [-q] (--connector-id ID | --location LOCATION)

Command options

--acl-id
Specify the ID of the ACL. To list all ACLs, run ibmcloud sat acl ls.
--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.
--subnet
An IP or CIDR block allowed by this ACL. Value must be fully contained in the following CIDRs: 10.0.0.0/8, 161.26.0.0/16, 166.8.0.0/14, 172.16.0.0/12.

Examples

Add one or more subnets to an ACL

ibmcloud sat acl subnet add --acl-id ID --subnet SUBNET --connector-id ID

ibmcloud sat acl subnet help

Show help

ibmcloud sat acl subnet help

Examples

Show help

ibmcloud sat acl subnet help

ibmcloud sat acl subnet rm

Satellite

Remove one or more subnets from an ACL.

ibmcloud sat acl subnet rm --acl-id ID --subnet SUBNET [--subnet SUBNET ...] [-q] (--connector-id ID | --location LOCATION)

Command options

--acl-id
Specify the ID of the ACL. To list all ACLs, run ibmcloud sat acl ls.
--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.
--subnet
An IP or CIDR block allowed by this ACL. Value must be fully contained in the following CIDRs: 10.0.0.0/8, 161.26.0.0/16, 166.8.0.0/14, 172.16.0.0/12.

Examples

Remove one or more subnets from an ACL

ibmcloud sat acl subnet rm --acl-id ID --subnet SUBNET --connector-id ID

ibmcloud sat acl update

Satellite

Update the name of an ACL.

ibmcloud sat acl update --acl-id ID --name NAME [-q] (--connector-id ID | --location LOCATION)

Command options

--acl-id
Specify the ID of the ACL. To list all ACLs, run ibmcloud sat acl ls.
--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--name
The new name for the ACL.
-q
Do not show the message of the day or update reminders.

Examples

Update the name of an ACL

ibmcloud sat acl update --acl-id ID --name NAME --connector-id ID

Agent commands

Attach or view Satellite Connector Agents.

ibmcloud sat agent attach

Satellite

Get a Satellite Connector Agent for a specific platform. Download the Agent .zip for Windows or get a link to the documentation for Docker environments.

ibmcloud sat agent attach --platform PLATFORM [-q]

Command options

--platform
The platform for the Satellite Connector Agent. For more information about Docker, see the documentation at https://ibm.biz/satconagent Available options: windows, docker
-q
Do not show the message of the day or update reminders.

Examples

Get a Satellite Connector Agent for a specific platform

ibmcloud sat agent attach --platform PLATFORM

ibmcloud sat agent help

Show help

ibmcloud sat agent help

Examples

Show help

ibmcloud sat agent help

ibmcloud sat agent ls

Satellite

List all Agents for a Satellite Connector.

ibmcloud sat agent ls --connector-id ID [--output OUTPUT] [-q]

Command options

--connector-id
The ID of a Satellite connector.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all Agents for a Satellite Connector

ibmcloud sat agent ls --connector-id ID

Cluster commands

Register and manage clusters for use with Satellite configurations.

ibmcloud sat cluster get

Virtual Private Cloud Classic infrastructure Satellite

Get the details of a registered cluster.

ibmcloud sat cluster get --cluster CLUSTER [--output OUTPUT] [-q]

Command options

-c, --cluster
Specify the cluster name or the ID. To list registered clusters, run ibmcloud sat cluster ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

Get the details of a registered cluster

ibmcloud sat cluster get --cluster CLUSTER

ibmcloud sat cluster help

Show help

ibmcloud sat cluster help

Examples

Show help

ibmcloud sat cluster help

ibmcloud sat cluster ls

Virtual Private Cloud Classic infrastructure Satellite

List all registered clusters in your IBM Cloud account.

ibmcloud sat cluster ls [--filter FILTER] [--limit LIMIT] [--output OUTPUT] [-q]

Command options

--filter
Filter registered clusters by cluster ID.
--limit
Limit the number of clusters that are returned.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all registered clusters in your IBM Cloud account

ibmcloud sat cluster ls

ibmcloud sat cluster register

Satellite

Get a kubectl command to register your cluster in a Satellite configuration. Log in to your cluster and run this command to install a Satellite Config agent. Clusters that you run in your Satellite location automatically install this agent.

ibmcloud sat cluster register --name NAME [-q] [--silent]

Command options

--name
Specify the name of the cluster that you want to register
-q
Do not show the message of the day or update reminders.
--silent
Silent. Return only the registration command in the output.

Examples

Get a kubectl command to register your cluster in a Satellite configuration

ibmcloud sat cluster register --name NAME

ibmcloud sat cluster unregister

Satellite

Remove a cluster registration. The cluster is no longer subscribed to a Satellite configuration, but the cluster and its existing resources still run.

ibmcloud sat cluster unregister --cluster CLUSTER [-f] [-q]

Command options

-c, --cluster
Specify the cluster name or the ID. To list registered clusters, run ibmcloud sat cluster ls.
-f
Force the command to run without user prompts.
-q
Do not show the message of the day or update reminders.

Examples

Remove a cluster registration

ibmcloud sat cluster unregister --cluster CLUSTER

Config commands

View and manage Satellite Configuration.

ibmcloud sat config create

Satellite

Create a configuration to specify what Kubernetes resources you want to deploy to your clusters in your Satellite workloads.

ibmcloud sat config create --name NAME [-q] (--data-location LOCATION | --provider PROVIDER)

Command options

--data-location
Specify the IBM region to store the Satellite configuration data. Strategy: Direct Upload.
--name
Provide a name for the Satellite configuration.
--provider
Indicate the remote GitOps provider for the Satellite configuration. This provider stores the Kubernetes resource definitions. Strategy: GitOps. Allowed values: github, gitlab
-q
Do not show the message of the day or update reminders.

Examples

Create a configuration to specify what Kubernetes resources you want to deploy to your clusters in your Satellite workloads

ibmcloud sat config create --name NAME --data-location LOCATION

ibmcloud sat config get

Satellite

Get details of a Satellite configuration, such as the versions or subscriptions that are associated with the configuration.

ibmcloud sat config get --config CONFIG [--output OUTPUT] [-q]

Command options

--config
Specify the name or ID of a Satellite configuration. To list available configurations, run ibmcloud sat config ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

Get details of a Satellite configuration, such as the versions or subscriptions that are associated with the configuration

ibmcloud sat config get --config CONFIG

ibmcloud sat config help

Show help

ibmcloud sat config help

Examples

Show help

ibmcloud sat config help

ibmcloud sat config ls

Satellite

List all Satellite configurations in your IBM Cloud account.

ibmcloud sat config ls [--output OUTPUT] [-q]

Command options

--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all Satellite configurations in your IBM Cloud account

ibmcloud sat config ls

ibmcloud sat config rename

Satellite

Rename a Satellite configuration.

ibmcloud sat config rename --config CONFIG --name NAME [-q]

Command options

--config
Specify the name or ID of a Satellite configuration. To list available configurations, run ibmcloud sat config ls.
--name
Provide a new name for the Satellite configuration.
-q
Do not show the message of the day or update reminders.

Examples

Rename a Satellite configuration

ibmcloud sat config rename --config CONFIG --name NAME

ibmcloud sat config rm

Satellite

Remove a Satellite configuration. All associated subscriptions must be removed first. All versions are deleted. Back up any resource definitions that you want to keep.

ibmcloud sat config rm --config CONFIG [-f] [-q]

Command options

--config
Specify the name or ID of a Satellite configuration. To list available configurations, run ibmcloud sat config ls.
-f
Force the command to run without user prompts.
-q
Do not show the message of the day or update reminders.

Examples

Remove a Satellite configuration

ibmcloud sat config rm --config CONFIG

ibmcloud sat config version create

Satellite

Create a configuration version to update existing Kubernetes resources for your Satellite workloads.

ibmcloud sat config version create --config CONFIG --file-format FORMAT --name NAME --read-config CONFIG [--description DESCRIPTION] [-q]

Command options

--config
Specify the name or ID of the Satellite configuration. To list available configurations, run ibmcloud sat config ls.
--description
Add a description for the Satellite configuration version.
--file-format
Indicate the file format of the configuration version. Available options: yaml
--name
Provide a name for the Satellite configuration version.
-q
Do not show the message of the day or update reminders.
--read-config
Specify the file path for the configuration version file.

Examples

Create a configuration version to update existing Kubernetes resources for your Satellite workloads

ibmcloud sat config version create \
  --config CONFIG \
  --file-format FORMAT \
  --name NAME \
  --read-config CONFIG

ibmcloud sat config version get

Satellite

Get details for a Satellite configuration version.

ibmcloud sat config version get --config CONFIG --version VERSION [--output OUTPUT] [-q] [--save-config]

Command options

--config
Specify the name or ID of the Satellite configuration. To list available configurations, run ibmcloud sat config ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.
--save-config
Download and save the configuration version to a temporary file.
--version
Specify the name or ID of the Satellite configuration version. To list versions in your configuration, run ibmcloud sat config get --config <configuration_name_or_ID>.

Examples

Get details for a Satellite configuration version

ibmcloud sat config version get --config CONFIG --version VERSION

ibmcloud sat config version help

Show help

ibmcloud sat config version help

Examples

Show help

ibmcloud sat config version help

ibmcloud sat config version rm

Satellite

Remove a Satellite configuration version.

ibmcloud sat config version rm --config CONFIG --version VERSION [-f] [-q]

Command options

--config
Specify the name or ID of the Satellite configuration. To list available configurations, run ibmcloud sat config ls.
-f
Force the command to run without user prompts.
-q
Do not show the message of the day or update reminders.
--version
Indicate the name or ID of the Satellite configuration version. To list versions, run ibmcloud sat config get --config <configuration_name_or_ID>.

Examples

Remove a Satellite configuration version

ibmcloud sat config version rm --config CONFIG --version VERSION

Connector commands

Create, view, and modify Satellite connectors.

ibmcloud sat connector create

Satellite

Create a Satellite connector.

ibmcloud sat connector create --name NAME --region REGION [-q]

Command options

--name
The name for the Satellite connector.
-q
Do not show the message of the day or update reminders.
--region
The IBM Cloud region to manage your Satellite connector.

Examples

Create a Satellite connector

ibmcloud sat connector create --name NAME --region REGION

ibmcloud sat connector get

Satellite

View the details of a Satellite Connector.

ibmcloud sat connector get --connector-id ID [--output OUTPUT] [-q]

Command options

--connector-id
The ID of a Satellite connector.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

View the details of a Satellite Connector

ibmcloud sat connector get --connector-id ID

ibmcloud sat connector help

Show help

ibmcloud sat connector help

Examples

Show help

ibmcloud sat connector help

ibmcloud sat connector ls

Satellite

View the Satellite Connectors in your IBM Cloud account.

ibmcloud sat connector ls [--after AFTER] [--first FIRST] [--output OUTPUT] [-q]

Command options

--after
Show Satellite Connectors after the given cursor.
--first
View the next Satellite Connectors, up to the first number of Connectors.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

View the Satellite Connectors in your IBM Cloud account

ibmcloud sat connector ls

ibmcloud sat connector rm

Satellite

Delete a Satellite connector.

ibmcloud sat connector rm --connector-id ID [-f] [-q]

Command options

--connector-id
The ID of a Satellite connector.
-f
Force the command to run without user prompts.
-q
Do not show the message of the day or update reminders.

Examples

Delete a Satellite connector

ibmcloud sat connector rm --connector-id ID

Endpoint commands

View and manage Satellite endpoints.

ibmcloud sat endpoint authn get

Satellite

Get the authentication settings for an endpoint.

ibmcloud sat endpoint authn get --endpoint ENDPOINT [--output OUTPUT] [-q] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--endpoint
Specify the name or ID of the endpoint. To list all endpoints, run ibmcloud sat endpoint ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

Get the authentication settings for an endpoint

ibmcloud sat endpoint authn get --endpoint ENDPOINT --connector-id ID

ibmcloud sat endpoint authn help

Show help

ibmcloud sat endpoint authn help

Examples

Show help

ibmcloud sat endpoint authn help

ibmcloud sat endpoint authn rotate

Satellite

Replace existing authentication certificates with new ones. There are two TLS connections in the request flow. The source options refer to the TLS handshake between the source and the Connector service. The destination options refer to the TLS handshake between the Connector service and your destination or target server. You can provide certificates for one or both of these connections. Only the certificates that you specify are replaced.

ibmcloud sat endpoint authn rotate --endpoint ENDPOINT [--dest-ca-cert-file FILE] [--dest-cert-file FILE] [--dest-key-file FILE] [-q] [--source-ca-cert-file FILE] [--source-cert-file FILE] [--source-key-file FILE] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--dest-ca-cert-file
Trusted CA certificate or chain used to validate the destination server's certificate. For example myCA.pem.
--dest-cert-file
The client certificate used to authenticate with the destination server. For example myCert.pem.
--dest-key-file
The client private key used to encrypt the client certificate. For example myKey.pem.
--endpoint
Specify the name or ID of the endpoint. To list all endpoints, run ibmcloud sat endpoint ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.
--source-ca-cert-file
Trusted CA certificate or chain used to validate the source client's certificate when source-tls-mode is mutual. For example myCA.pem.
--source-cert-file
The server certificate to present to the source client. For example myCert.pem.
--source-key-file
The server private key used to encrypt the server certificate. For example myKey.pem.

Examples

Replace existing authentication certificates with new ones

ibmcloud sat endpoint authn rotate --endpoint ENDPOINT --connector-id ID

ibmcloud sat endpoint authn set

Satellite

Set authentication settings for an endpoint. There are two TLS connections in the request flow. The source options refer to the TLS handshake between the source and the Connector service. The destination options refer to the TLS handshake between the Connector service and your destination or target server. You can provide certificates for one or both of these connections. Unspecified settings are set to their default values.

ibmcloud sat endpoint authn set --endpoint ENDPOINT [--dest-ca-cert-file FILE] [--dest-cert-file FILE] [--dest-key-file FILE] [--dest-tls-mode MODE] [-q] [--source-ca-cert-file FILE] [--source-cert-file FILE] [--source-key-file FILE] [--source-tls-mode MODE] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--dest-ca-cert-file
Trusted CA certificate or chain used to validate the destination server's certificate. For example myCA.pem.
--dest-cert-file
The client certificate used to authenticate with the destination server. For example myCert.pem.
--dest-key-file
The client private key used to encrypt the client certificate. For example myKey.pem.
--dest-tls-mode
The destination TLS mode. Accepted values: simple, mutual, none
--endpoint
Specify the name or ID of the endpoint. To list all endpoints, run ibmcloud sat endpoint ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.
--source-ca-cert-file
Trusted CA certificate or chain used to validate the source client's certificate when source-tls-mode is mutual. For example myCA.pem.
--source-cert-file
The server certificate to present to the source client. For example myCert.pem.
--source-key-file
The server private key used to encrypt the server certificate. For example myKey.pem.
--source-tls-mode
The source TLS mode. Accepted values: simple, mutual

Examples

Set authentication settings for an endpoint

ibmcloud sat endpoint authn set --endpoint ENDPOINT --connector-id ID

ibmcloud sat endpoint create

Satellite

Create an endpoint.

ibmcloud sat endpoint create --dest-hostname HOSTNAME --dest-port PORT --dest-type TYPE --name NAME --source-protocol PROTOCOL [--dest-protocol PROTOCOL] [--idle-timeout-seconds SECONDS] [--output OUTPUT] [-q] [--sni SNI] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--dest-hostname
Indicate the fully qualified domain name (FQDN) or the externally accessible IP address of the destination that you want to connect to. For cloud endpoints, this value must resolve to a public IP address or to a private IP address that is accessible within IBM Cloud such as a private cloud service endpoint. For location endpoints, this value must resolve from and be reachable from the control plane hosts for Satellite locations or where the agent runs for Satellite Connector.
--dest-port
Provide the port that the destination resource listens on for incoming requests. Make sure that the port matches the destination protocol.
--dest-protocol
Specify the destination's protocol. If you do not specify this option, the destination protocol is inherited from the source protocol. Accepted values: TCP, TLS
--dest-type
Specify where the destination resource runs, either in IBM Cloud (cloud) or your Satellite location (location). Available options: location, cloud
--idle-timeout-seconds
Specify the timeout interval in seconds for active connections to the destination. Make sure your timeout is compatible with the destination service and protocol keep-alive settings.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--name
Provide a name for the endpoint.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.
--sni
Specify the server name indicator, if you specify a tls or https source protocol and want a separate hostname to be added to the TLS handshake.
--source-protocol
Provide the protocol that the source uses to connect the destination resource. See http://ibm.biz/endpoint-protocols. Available options: TCP, TLS, HTTP, HTTPS, HTTP-tunnel

Examples

Create an endpoint

ibmcloud sat endpoint create \
  --dest-hostname HOSTNAME \
  --dest-port PORT \
  --dest-type TYPE \
  --name NAME \
  --source-protocol PROTOCOL \
  --connector-id ID

ibmcloud sat endpoint disable

Satellite

Disable an endpoint.

ibmcloud sat endpoint disable --endpoint ENDPOINT [-f] [-q] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--endpoint
Specify the name or ID of the endpoint. To list all endpoints, run ibmcloud sat endpoint ls (--connector-id ID | --location LOCATION).
-f
Force the command to run without user prompts.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.

Examples

Disable an endpoint

ibmcloud sat endpoint disable --endpoint ENDPOINT --connector-id ID

ibmcloud sat endpoint enable

Satellite

Enable an endpoint.

ibmcloud sat endpoint enable --endpoint ENDPOINT [-f] [-q] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--endpoint
Specify the name or ID of the endpoint. To list all endpoints, run ibmcloud sat endpoint ls (--connector-id ID | --location LOCATION).
-f
Force the command to run without user prompts.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.

Examples

Enable an endpoint

ibmcloud sat endpoint enable --endpoint ENDPOINT --connector-id ID

ibmcloud sat endpoint get

Satellite

View the details of an endpoint.

ibmcloud sat endpoint get --endpoint ENDPOINT [--output OUTPUT] [-q] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--endpoint
Specify the name or ID of the endpoint. To list all endpoints, run ibmcloud sat endpoint ls (--connector-id ID | --location LOCATION).
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

View the details of an endpoint

ibmcloud sat endpoint get --endpoint ENDPOINT --connector-id ID

ibmcloud sat endpoint help

Show help

ibmcloud sat endpoint help

Examples

Show help

ibmcloud sat endpoint help

ibmcloud sat endpoint ls

Satellite

List all endpoints in a Satellite location.

ibmcloud sat endpoint ls [--output OUTPUT] [-q] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all endpoints in a Satellite location

ibmcloud sat endpoint ls --connector-id ID

ibmcloud sat endpoint rm

Satellite

Delete an endpoint.

ibmcloud sat endpoint rm --endpoint ENDPOINT [-q] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--endpoint
Specify the name or ID of the endpoint. To list all endpoints, run ibmcloud sat endpoint ls (--connector-id ID | --location LOCATION).
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.

Examples

Delete an endpoint

ibmcloud sat endpoint rm --endpoint ENDPOINT --connector-id ID

ibmcloud sat endpoint update

Satellite

Update an endpoint. Only the options that you specify are updated.

ibmcloud sat endpoint update --endpoint ENDPOINT [--dest-hostname HOSTNAME] [--dest-port PORT] [--dest-protocol PROTOCOL] [--idle-timeout-seconds SECONDS] [--name NAME] [-q] [--sni SNI] [--source-protocol PROTOCOL] (--connector-id ID | --location LOCATION)

Command options

--connector-id
The ID of the Satellite connector. To find the connector ID, run ibmcloud sat connector ls.
--dest-hostname
Indicate the fully qualified domain name (FQDN) or the externally accessible IP address of the destination that you want to connect to. For cloud endpoints, this value must resolve to a public IP address or to a private IP address that is accessible within IBM Cloud such as a private cloud service endpoint. For location endpoints, this value must resolve from and be reachable from the control plane hosts for Satellite locations or where the agent runs for Satellite Connector.
--dest-port
Provide the port that the destination resource listens on for incoming requests. Make sure that the port matches the destination protocol.
--dest-protocol
Specify the destination's protocol. If you do not specify this option, the destination protocol is inherited from the source protocol. Accepted values: TCP, TLS
--endpoint
Specify the name or ID of the endpoint. To list all endpoints, run ibmcloud sat endpoint ls (--connector-id ID | --location LOCATION).
--idle-timeout-seconds
Specify the timeout interval in seconds for active connections to the destination. Make sure your timeout is compatible with the destination service and protocol keep-alive settings.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--name
Provide a new name for the endpoint.
-q
Do not show the message of the day or update reminders.
--sni
Specify the server name indicator, if you specify a tls or https source protocol and want a separate hostname to be added to the TLS handshake.
--source-protocol
Provide the protocol that the source uses to connect the destination resource. See http://ibm.biz/endpoint-protocols. Accepted values: TCP, TLS, HTTP, HTTPS, HTTP-tunnel

Examples

Update an endpoint

ibmcloud sat endpoint update --endpoint ENDPOINT --connector-id ID

Experimental commands

[Expires on 2024-11-25] Experiment with new commands. IMPORTANT: Commands here will retire after the [date] in their description.

ibmcloud sat experimental endpoint help

Show help

ibmcloud sat experimental endpoint help

Examples

Show help

ibmcloud sat experimental endpoint help

ibmcloud sat experimental help

Show help

ibmcloud sat experimental help

Examples

Show help

ibmcloud sat experimental help

Group commands

View and manage Satellite cluster groups. Cluster groups are used to subscribe clusters to Satellite configurations of Kubernetes resources.

ibmcloud sat group attach

Satellite

Add a cluster to your cluster group. The cluster can run in your Satellite location or in IBM Cloud. To add a cluster that runs in IBM Cloud, you must first register the cluster with Satellite Config.

ibmcloud sat group attach --cluster CLUSTER [--cluster CLUSTER ...] --group GROUP [-q]

Command options

-c, --cluster
Specify the cluster name or ID. To list registered clusters, run ibmcloud sat cluster ls.
-g, --group
Specify the name or ID of a Satellite cluster group. To list available cluster groups, run ibmcloud sat group ls.
-q
Do not show the message of the day or update reminders.

Examples

Add a cluster to your cluster group

ibmcloud sat group attach --cluster CLUSTER --group GROUP

ibmcloud sat group create

Satellite

Create a cluster group. Then, you can subscribe the cluster group to a Satellite configuration.

ibmcloud sat group create --name NAME [--cluster CLUSTER ...] [-q]

Command options

-c, --cluster
Specify the cluster name or ID to add to the cluster group. To list registered clusters, run ibmcloud sat cluster ls.
--name
Provide a name of the Satellite cluster group.
-q
Do not show the message of the day or update reminders.

Examples

Create a cluster group

ibmcloud sat group create --name NAME

ibmcloud sat group detach

Satellite

Removes one or more clusters from your Satellite cluster group and deletes the Kubernetes resources that were managed by the group's subscriptions.

ibmcloud sat group detach --cluster CLUSTER [--cluster CLUSTER ...] --group GROUP [-f] [-q]

Command options

-c, --cluster
Specify the cluster name or ID. To list the clusters in your cluster group, run ibmcloud sat group get --group <cluster_group_name_or_ID>.
-f
Force the command to run without user prompts.
-g, --group
Specify the name or ID of a Satellite cluster group. To list available cluster groups, run ibmcloud sat group ls.
-q
Do not show the message of the day or update reminders.

Examples

Removes one or more clusters from your Satellite cluster group and deletes the Kubernetes resources that were managed by the group's subscriptions

ibmcloud sat group detach --cluster CLUSTER --group GROUP

ibmcloud sat group get

Satellite

Get detailed information for a Satellite cluster group.

ibmcloud sat group get --group GROUP [--output OUTPUT] [-q]

Command options

-g, --group
Specify the name or ID of a Satellite cluster group. To list registered clusters, run ibmcloud sat cluster ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

Get detailed information for a Satellite cluster group

ibmcloud sat group get --group GROUP

ibmcloud sat group help

Show help

ibmcloud sat group help

Examples

Show help

ibmcloud sat group help

ibmcloud sat group ls

Satellite

List all Satellite cluster groups in your IBM Cloud account.

ibmcloud sat group ls [--output OUTPUT] [-q]

Command options

--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all Satellite cluster groups in your IBM Cloud account

ibmcloud sat group ls

ibmcloud sat group rm

Satellite

Remove a Satellite cluster group, which unsubscribes clusters and deletes the Kubernetes resources that were managed by the group's subscriptions.

ibmcloud sat group rm --group GROUP [-f] [-q]

Command options

-f
Force the command to run without user prompts.
-g, --group
Specify the name or ID of a Satellite cluster group. To list available cluster groups, run ibmcloud sat group ls.
-q
Do not show the message of the day or update reminders.

Examples

Remove a Satellite cluster group, which unsubscribes clusters and deletes the Kubernetes resources that were managed by the group's subscriptions

ibmcloud sat group rm --group GROUP

Host commands

View and modify Satellite hosts.

ibmcloud sat host assign

Satellite

Assign a host to a Satellite location control plane or cluster.

ibmcloud sat host assign --location LOCATION [--cluster CLUSTER] [--host HOST] [--host-label LABEL ...] [-q] [--worker-pool POOL] [--zone ZONE]

Command options

--cluster
The name or ID of the cluster to assign the host to. To list available clusters, run ibmcloud sat cluster ls. If no cluster is provided, the host is automatically assigned to the Satellite control plane.
--host
The name or ID of the host to assign. To automatically assign hosts based on labels, do not include this option. To retrieve the host ID, run ibmcloud sat host ls --location <location_ID_or_name>.
--host-label, --hl
Enter any labels as key-value pairs to identify the host to assign to your Satellite control plane or Red Hat OpenShift cluster. The first host that has this label and is unassigned is automatically assigned to the control plane or cluster. To find available host labels, run ibmcloud sat host get --host <host_name_or_ID> --location <location_name_or_ID>.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-p, --worker-pool
The name or ID of the worker pool within the cluster to assign the host. If no worker pool is specified, the host is assigned to the default worker pool.
-q
Do not show the message of the day or update reminders.
--zone
The name or ID of the zone to assign the host. To find available zones, run ibmcloud sat location get --location <location_name_or_ID> and look for the Host Zones field.

Examples

Assign a host to a Satellite location control plane or cluster

ibmcloud sat host assign --location LOCATION

ibmcloud sat host attach

Satellite

Create and download a script that you can run on your hosts to attach them to your location. For RHCOS enabled locations, the script is an ignition file.

ibmcloud sat host attach --location LOCATION [--host-label LABEL ...] [--host-link-agent-endpoint ENDPOINT] [--operating-system SYSTEM] [-q] [--reset-key]

Command options

--host-label, --hl
Enter any labels as key-value pairs to identify the host to assign to your Satellite control plane or Red Hat OpenShift cluster. The first host that has this label and is unassigned is automatically assigned to the control plane or cluster. To find available host labels, run ibmcloud sat host get --host <host_name_or_ID> --location <location_name_or_ID>.
--host-link-agent-endpoint
The endpoint that the link agent uses to connect to the link tunnel server.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--operating-system
The operating system of the hosts you want to attach to your location. To attach RHCOS hosts, your location must be RHCOS enabled. Accepted values: RHEL, RHCOS
-q
Do not show the message of the day or update reminders.
--reset-key
Reset the key that the control plane uses to attach and assign hosts in the location. See https://ibm.biz/reset-key.

Examples

Create and download a script that you can run on your hosts to attach them to your location

ibmcloud sat host attach --location LOCATION

ibmcloud sat host get

Satellite

View the details of a Satellite host.

ibmcloud sat host get --host HOST --location LOCATION [--output OUTPUT] [-q]

Command options

--host
The Satellite host ID. To find the host ID, run ibmcloud sat host ls <location_ID_or_name>.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

View the details of a Satellite host

ibmcloud sat host get --host HOST --location LOCATION

ibmcloud sat host help

Show help

ibmcloud sat host help

Examples

Show help

ibmcloud sat host help

ibmcloud sat host ls

Satellite

List all hosts that are attached to a Satellite location, including hosts that are assigned to clusters or the control plane.

ibmcloud sat host ls --location LOCATION [--output OUTPUT] [-q]

Command options

--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all hosts that are attached to a Satellite location, including hosts that are assigned to clusters or the control plane

ibmcloud sat host ls --location LOCATION

ibmcloud sat host rm

Satellite

Remove a host from a Satellite location.

ibmcloud sat host rm --host HOST --location LOCATION [-f] [-q]

Command options

-f
Force the command to run without user prompts.
--host
The name or ID of the host to remove.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.

Examples

Remove a host from a Satellite location

ibmcloud sat host rm --host HOST --location LOCATION

ibmcloud sat host update

Satellite

Update host information, such as zones and labels.

ibmcloud sat host update --host HOST --location LOCATION [--host-label LABEL ...] [-q] [--zone ZONE]

Command options

--host
The name or ID of the host to assign. To automatically assign hosts based on labels, do not include this option.
--host-label, --hl
Enter any labels as key-value pairs to identify the host to assign to your Satellite control plane or Red Hat OpenShift cluster. The first host that has this label and is unassigned is automatically assigned to the control plane or cluster. To find available host labels, run ibmcloud sat host get --host <host_name_or_ID> --location <location_name_or_ID>.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.
--zone
The name or ID of the zone to associate the host. You cannot change the zone of hosts that are assigned to a resource, such as a cluster. You must unassign them first. To list available zones, run ibmcloud sat location get --location <ID>.

Examples

Update host information, such as zones and labels

ibmcloud sat host update --host HOST --location LOCATION

Key commands

View and manage Satellite Config keys.

ibmcloud sat key help

Show help

ibmcloud sat key help

Examples

Show help

ibmcloud sat key help

ibmcloud sat key ls

Satellite

List all Satellite Config keys in your IBM Cloud account.

ibmcloud sat key ls [--output OUTPUT] [-q]

Command options

--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all Satellite Config keys in your IBM Cloud account

ibmcloud sat key ls

ibmcloud sat key rm

Satellite

Remove a Satellite Config key. Any cluster that still uses this key cannot connect to Satellite Config.

ibmcloud sat key rm --key KEY [-f] [-q]

Command options

-f
Force the command to run without user prompts.
--key
The name or ID of a Satellite Config key.
-q
Do not show the message of the day or update reminders.

Examples

Remove a Satellite Config key

ibmcloud sat key rm --key KEY

ibmcloud sat key rotate

Satellite

Generate a new key for use by managed clusters to connect to Satellite Config.

ibmcloud sat key rotate --name NAME [-f] [-q]

Command options

-f
Force the command to run without user prompts.
--name
The name of the new Satellite Config key.
-q
Do not show the message of the day or update reminders.

Examples

Generate a new key for use by managed clusters to connect to Satellite Config

ibmcloud sat key rotate --name NAME

Location commands

Create, view, and modify Satellite locations.

ibmcloud sat location create

Satellite

Create a Satellite location. A Satellite location is a representation of an environment in your infrastructure provider. After you create a location, attach hosts from separate zones of your backing infrastructure environment with the ibmcloud sat host attach command.

ibmcloud sat location create --managed-from REGION --name NAME [--capability CAPABILITY ...] [--coreos-enabled] [--cos-bucket BUCKET] [--description DESCRIPTION] [--ha-zone ZONE ...] [--physical-address ADDRESS] [--pod-network-interface-selection SELECTION] [--pod-subnet SUBNET] [--provider PROVIDER] [--provider-credential CREDENTIAL] [--provider-region REGION] [-q] [--service-subnet SUBNET]

Command options

--capability
A capability of the Satellite location.
--coreos-enabled
Enable Red Hat CoreOS features for the Satellite location. This action cannot be undone. See https://ibm.biz/infra-os.
--cos-bucket
Specify the name of the IBM Cloud Object Storage bucket to store your Satellite location control plane data. Otherwise, a new bucket is created for you.
--description
Enter a description for the Satellite location.
--ha-zone
Specify the zone for your location. For high availability, specify 3 zones for your location as --ha-zone ZONE1_NAME --ha-zone ZONE2_NAME --ha-zone ZONE3_NAME. The names of the zones must match exactly the names of the corresponding zones in your infrastructure provider where you plan to create hosts.
--managed-from
Select the IBM Cloud region to manage your Satellite location from. Choose a region close to your on-prem data center for better performance. See https://ibm.biz/sat-region.
--name
Specify a name for the Satellite location. Location names must start with a letter, can contain letters, numbers, periods (.), and hyphen (-), and must be fewer than 36 characters. Do not reuse names, even if the other location is deleted.
--physical-address
The physical address of the Satellite location.
--pod-network-interface-selection
The method for selecting the node network interface for the internal pod network. This option can be used only if you also enable Red Hat CoreOS with the --coreos-enabled option. To provide a direct URL or IP address, specify can-reach=<url> or can-reach=<ip_address>. To choose a network interface, specify interface=<network_interface>.
--pod-subnet
Specify a custom subnet CIDR to provide private IP addresses for pods. This option is used only if you enable Red Hat CoreOS with the --coreos-enabled option. The subnet must be /23 or larger. See https://ibm.biz/sat-location-create. Default value: '172.16.0.0/16
--provider
Indicate the infrastructure provider to use for the Satellite location. If you include this option, you must also include the --provider-credential option. Accepted values: aws, azure, gcp, vmware
--provider-credential
Specify the path to a JSON file on your local machine that has the credentials of the infrastructure provider for the Satellite location. The credential format is provider-specific. See http://ibm.biz/sat-infra-creds.
--provider-region
Specify the region in the infrastructure provider where you plan to create the hosts for the Satellite location. If you include this option, you must also include the --provider option.
-q
Do not show the message of the day or update reminders.
--service-subnet
Specify a custom subnet CIDR to provide private IP addresses for services. This option is used only if you enable Red Hat CoreOS with the --coreos-enabled option. The subnet must be /24 or larger. See https://ibm.biz/sat-location-create. Default value: 172.20.0.0/16

Examples

Create a Satellite location

ibmcloud sat location create --managed-from REGION --name NAME

ibmcloud sat location dns get

Satellite

View the details of a registered subdomain in a Satellite location.

ibmcloud sat location dns get --location LOCATION --subdomain SUBDOMAIN [--output OUTPUT] [-q]

Command options

--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.
--subdomain
Specify the subdomain name. To list existing subdomains, run ibmcloud sat location dns ls --location <ID>.

Examples

View the details of a registered subdomain in a Satellite location

ibmcloud sat location dns get --location LOCATION --subdomain SUBDOMAIN

ibmcloud sat location dns help

Show help

ibmcloud sat location dns help

Examples

Show help

ibmcloud sat location dns help

ibmcloud sat location dns ls

Satellite

List the registered subdomains in a Satellite location.

ibmcloud sat location dns ls --location LOCATION [--output OUTPUT] [-q]

Command options

--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List the registered subdomains in a Satellite location

ibmcloud sat location dns ls --location LOCATION

ibmcloud sat location dns register

Satellite

Set a subdomain for the hosts assigned to the control plane in a Satellite location.

ibmcloud sat location dns register --ip IP [--ip IP ...] --location LOCATION [--output OUTPUT] [-q]

Command options

--ip
Specify the IP address for each control plane host, in the format --ip x.x.x.1 --ip x.x.x.2 --ip x.x.x.3. For multizone clusters, use one IP address from each zone. To find the IP address, run ibmcloud sat host ls --location <location_ID_or_name> and look for Worker IP for hosts labeled infrastructure.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

Set a subdomain for the hosts assigned to the control plane in a Satellite location

ibmcloud sat location dns register --ip IP --location LOCATION

ibmcloud sat location get

Satellite

View the details of a Satellite location.

ibmcloud sat location get --location LOCATION [--output OUTPUT] [-q]

Command options

--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

View the details of a Satellite location

ibmcloud sat location get --location LOCATION

ibmcloud sat location help

Show help

ibmcloud sat location help

Examples

Show help

ibmcloud sat location help

ibmcloud sat location ls

Satellite

List all Satellite locations in your IBM Cloud account.

ibmcloud sat location ls [--output OUTPUT] [-q]

Command options

--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all Satellite locations in your IBM Cloud account

ibmcloud sat location ls

ibmcloud sat location rm

Satellite

Delete a location. Before you run this command, back up your configurations and remove any hosts and clusters that run in the location. The underlying host infrastructure is not automatically deleted when you delete a location. This action cannot be undone.

ibmcloud sat location rm --location LOCATION [-f] [-q]

Command options

-f
Force the command to run without user prompts.
--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
-q
Do not show the message of the day or update reminders.

Examples

Delete a location

ibmcloud sat location rm --location LOCATION

ibmcloud sat location update

Satellite

Update the name or description of a Satellite location.

ibmcloud sat location update --location-id ID [--description DESCRIPTION] [--name NAME] [-q]

Command options

--description
Enter a new description for the Satellite location. The length of the description is limited to 400 bytes.
--location-id
The ID of the Satellite location. To find the location ID, run ibmcloud sat location ls.
--name
Specify a new name for the Satellite location. Location names must start with a letter, can contain letters, numbers, periods (.), and hyphen (-), and must be fewer than 36 characters. Do not reuse names, including names of deleted locations.
-q
Do not show the message of the day or update reminders.

Examples

Update the name or description of a Satellite location

ibmcloud sat location update --location-id ID

Messages commands

View the current user messages.

ibmcloud sat messages

Virtual Private Cloud Classic infrastructure Satellite

View the current user messages.

ibmcloud sat messages [-q]

Command options

-q
Do not show the message of the day or update reminders.

Examples

View the current user messages

ibmcloud sat messages

Resource commands

Search and view Kubernetes resources that are managed by a Satellite configuration.

ibmcloud sat resource get

Satellite

View the details of a Kubernetes resource that is managed by a Satellite configuration.

ibmcloud sat resource get --resource RESOURCE [--history HISTORY] [--output OUTPUT] [-q] [--save-data]

Command options

--history
The history ID for the resource.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.
--resource
Specify the Kubernetes resource ID. To find Kubernetes resources, run ibmcloud sat resource ls.
--save-data
Download and save a Kubernetes resource definition to a temporary file.

Examples

View the details of a Kubernetes resource that is managed by a Satellite configuration

ibmcloud sat resource get --resource RESOURCE

ibmcloud sat resource help

Show help

ibmcloud sat resource help

Examples

Show help

ibmcloud sat resource help

ibmcloud sat resource history get

Satellite

Get history for a Kubernetes resource.

ibmcloud sat resource history get --resource RESOURCE [--limit LIMIT] [--output OUTPUT] [-q]

Command options

--limit
Specify the maximum number of history entries to return.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.
--resource
The Kubernetes resource ID.

Examples

Get history for a Kubernetes resource

ibmcloud sat resource history get --resource RESOURCE

ibmcloud sat resource history help

Show help

ibmcloud sat resource history help

Examples

Show help

ibmcloud sat resource history help

ibmcloud sat resource ls

Satellite

Search Kubernetes resources that are managed by Satellite.

ibmcloud sat resource ls [--limit LIMIT] [--output OUTPUT] [-q] [--search SEARCH] (--cluster CLUSTER | --subscription SUBSCRIPTION)

Command options

-c, --cluster
Specify the name or ID of the registered cluster that the Kubernetes resource runs in. To find registered clusters, run ibmcloud sat cluster ls.
--limit
Specify the maximum number of resource entries for the search to return.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.
--search
Indicate the string to filter search results of Kubernetes resources, such as a pod or namespace name.
--subscription
Specify the Satellite subscription ID or name. To find subscriptions, run ibmcloud sat cluster ls.

Examples

Search Kubernetes resources that are managed by Satellite

ibmcloud sat resource ls --cluster CLUSTER

Service commands

View Satellite service clusters.

ibmcloud sat service help

Show help

ibmcloud sat service help

Examples

Show help

ibmcloud sat service help

ibmcloud sat service ls

Satellite

List all Satellite service clusters in your location to review details, such as requested host resources.

ibmcloud sat service ls --location LOCATION [--output OUTPUT] [-q]

Command options

--location
The name or ID of the Satellite location. To find the location ID or name, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all Satellite service clusters in your location to review details, such as requested host resources

ibmcloud sat service ls --location LOCATION

Storage commands

View and manage Satellite storage resources.

ibmcloud sat storage assignment autopatch disable

The storage assignment autopatch disable command is a beta feature.

Satellite

Disable automatic patches for a Satellite storage assignment.

ibmcloud sat storage assignment autopatch disable --config CONFIG [-q] (--all | --assignment ASSIGNMENT)

Command options

--all
Disable automatic patches for all Satellite storage assignments of a storage configuration.
--assignment
The ID of a Satellite storage assignment. To list available storage assignments of the configuration, run ibmcloud sat storage assignment ls --config CONFIG.
--config
The name or ID of a Satellite storage configuration. To list available storage configurations, run ibmcloud sat storage config ls.
-q
Do not show the message of the day or update reminders.

Examples

Disable automatic patches for a Satellite storage assignment

ibmcloud sat storage assignment autopatch disable --config CONFIG --all

ibmcloud sat storage assignment autopatch enable

The storage assignment autopatch enable command is a beta feature.

Satellite

Enable automatic patches for a Satellite storage assignment.

ibmcloud sat storage assignment autopatch enable --config CONFIG [-q] (--all | --assignment ASSIGNMENT)

Command options

--all
Enable automatic patches for all Satellite storage assignments of a storage configuration.
--assignment
The ID of a Satellite storage assignment. To list available storage assignments of the configuration, run ibmcloud sat storage assignment ls --config CONFIG.
--config
The name or ID of a Satellite storage configuration. To list available storage configurations, run ibmcloud sat storage config ls.
-q
Do not show the message of the day or update reminders.

Examples

Enable automatic patches for a Satellite storage assignment

ibmcloud sat storage assignment autopatch enable --config CONFIG --all

ibmcloud sat storage assignment autopatch help

Show help

ibmcloud sat storage assignment autopatch help

Examples

Show help

ibmcloud sat storage assignment autopatch help

ibmcloud sat storage assignment create

Satellite

Create an assignment to deploy your storage configurations to clusters in your Satellite location.

ibmcloud sat storage assignment create --config CONFIG [--name NAME] [-q] (--cluster CLUSTER | --group GROUP | --service-cluster-id CLUSTER)

Command options

-c, --cluster
Specify the ID of the Satellite cluster for the assignment. To find the cluster ID, run ibmcloud oc cluster ls --provider satellite.
--config
Specify the Satellite storage configuration for the assignment. to find configurations, run ibmcloud sat storage config ls.
-g, --group
Specify the cluster groups for the assignment. To find cluster groups, run ibmcloud sat group ls.
--name
Provide a name for Satellite storage assignment.
-q
Do not show the message of the day or update reminders.
--service-cluster-id
Specify the ID of the service cluster for the assignment. To find the service cluster ID, run ibmcloud sat service ls --location <location>.

Examples

Create an assignment to deploy your storage configurations to clusters in your Satellite location

ibmcloud sat storage assignment create --config CONFIG --cluster CLUSTER

ibmcloud sat storage assignment get

Satellite

Get the details of a Satellite storage assignment.

ibmcloud sat storage assignment get --assignment ASSIGNMENT [--output OUTPUT] [-q]

Command options

--assignment
Specify the ID of a Satellite storage assignment.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

Get the details of a Satellite storage assignment

ibmcloud sat storage assignment get --assignment ASSIGNMENT

ibmcloud sat storage assignment help

Show help

ibmcloud sat storage assignment help

Examples

Show help

ibmcloud sat storage assignment help

ibmcloud sat storage assignment ls

Satellite

List the Satellite storage assignments in your IBM Cloud account.

To list all assignments for a service cluster as Service Admin: ibmcloud sat storage assignment ls --service-cluster-id CLUSTER.

To list all assignments for a service cluster as Location Admin: ibmcloud sat storage assignment ls --location LOCATION --service-cluster-id CLUSTER.

To list all assignments for a configuration: ibmcloud sat storage assignment ls --config CONFIG.

ibmcloud sat storage assignment ls [--output OUTPUT] [-q] (--cluster CLUSTER | --config CONFIG | --location LOCATION | --service-cluster-id CLUSTER)

Command options

-c, --cluster
Specify the ID of the Satellite cluster for the assignments. To get the cluster ID, run ibmcloud oc cluster ls --provider satellite.
--config
Specify the name or ID of a Satellite storage configuration. To list available storage configurations, run ibmcloud sat storage config ls.
--location
Specify the name of a Satellite location. To list available locations, run ibmcloud sat location ls. This option cannot be used by service administrator.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.
--service-cluster-id
Specify the ID of the service cluster for the assignments. To find the service cluster ID, run ibmcloud sat service ls --location <location>.

Examples

List the Satellite storage assignments in your IBM Cloud account

ibmcloud sat storage assignment ls --cluster CLUSTER

ibmcloud sat storage assignment patch

Satellite

Apply storage configuration changes to the associated assignments.

ibmcloud sat storage assignment patch --assignment ASSIGNMENT [-f] [-q]

Aliases: ibmcloud sat upgrade

Command options

--assignment
Specify the ID of a Satellite storage assignment. To list available assignments, run ibmcloud sat storage assignment ls.
-f
Force the command to run without user prompts.
-q
Do not show the message of the day or update reminders.

Examples

Apply storage configuration changes to the associated assignments

ibmcloud sat storage assignment patch --assignment ASSIGNMENT

ibmcloud sat storage assignment rm

Satellite

Remove a Satellite storage assignment. The Kubernetes resources are deleted from all the clusters in your Satellite location, but the configuration remains.

ibmcloud sat storage assignment rm --assignment ASSIGNMENT [-f] [-q]

Command options

--assignment
Specify the ID of a Satellite storage assignment. To find assignments, run ibmcloud sat storage assignment ls.
-f
Force the command to run without user prompts.
-q
Do not show the message of the day or update reminders.

Examples

Remove a Satellite storage assignment

ibmcloud sat storage assignment rm --assignment ASSIGNMENT

ibmcloud sat storage assignment update

Satellite

Update a Satellite storage assignment.

ibmcloud sat storage assignment update --assignment ASSIGNMENT [-f] [--group GROUP ...] [--name NAME] [-q]

Command options

--assignment
Specify the ID of a Satellite storage assignment.
-f
Force the command to run without user prompts.
-g, --group
Specify the new cluster groups for the assignment. To list available groups, run ibmcloud sat group ls.
--name
Provide a new name for the Satellite storage assignment.
-q
Do not show the message of the day or update reminders.

Examples

Update a Satellite storage assignment

ibmcloud sat storage assignment update --assignment ASSIGNMENT

ibmcloud sat storage config class add

Satellite

Create a custom Satellite storage class.

ibmcloud sat storage config class add --config-name NAME --name NAME --param PARAM [--param PARAM ...] [-q]

Command options

--config-name
Specify the name of the storage configuration for the custom storage class. To list Satellite storage configurations, run ibmcloud sat storage config ls.
--name
Provide a name for the custom storage class.
-p, --param
Specify a key=value pair for storage class parameters. To see the storage class parameters in a storage template, run ibmcloud sat storage template get.
-q
Do not show the message of the day or update reminders.

Examples

Create a custom Satellite storage class

ibmcloud sat storage config class add --config-name NAME --name NAME --param PARAM

ibmcloud sat storage config class get

Satellite

Get the details of a Satellite storage class.

ibmcloud sat storage config class get --class CLASS --config CONFIG [--output OUTPUT] [-q]

Command options

--class
Specify the name of a Satellite storage class.
--config
Specify the name or ID of a Satellite storage configuration. To list Satellite storage configurations, run ibmcloud sat storage config ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

Get the details of a Satellite storage class

ibmcloud sat storage config class get --class CLASS --config CONFIG

ibmcloud sat storage config class help

Show help

ibmcloud sat storage config class help

Examples

Show help

ibmcloud sat storage config class help

ibmcloud sat storage config class ls

Satellite

List the storage classes in a Satellite storage configuration

ibmcloud sat storage config class ls --config CONFIG [--output OUTPUT] [-q] [--show-params]

Command options

--config
Specify the name or ID of a Satellite storage configuration. To list Satellite storage configurations, run ibmcloud sat storage config ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.
--show-params
Include this option to list all storage class parameter details.

Examples

List the storage classes in a Satellite storage configuration

ibmcloud sat storage config class ls --config CONFIG

ibmcloud sat storage config create

Satellite

Create a Satellite storage configuration to install storage drivers in your clusters.

ibmcloud sat storage config create --location LOCATION --name NAME --template-name NAME [--param PARAM ...] [-q] [--template-version VERSION]

Command options

--location
Enter the ID or name of the location for the storage configuration. To find available locations, run ibmcloud sat location ls.
--name
Specify the name of the storage configuration.
-p, --param
Specify a key=value pair for configuration parameters. To see the configuration parameters in a storage template, run ibmcloud sat storage template get.
-q
Do not show the message of the day or update reminders.
--template-name
Specify the Satellite storage configuration template name. To list available storage configuration templates, run ibmcloud sat storage template ls.
--template-version
Specify the Satellite storage configuration template version. If you do not include this option, the default version is used. To list available storage configuration templates, run ibmcloud sat storage template ls.

Examples

Create a Satellite storage configuration to install storage drivers in your clusters

ibmcloud sat storage config create --location LOCATION --name NAME --template-name NAME

ibmcloud sat storage config get

Satellite

Get the details of a Satellite storage configuration.

ibmcloud sat storage config get --config CONFIG [--output OUTPUT] [-q]

Command options

--config
Specify the name or ID of a Satellite storage configuration. To list available configurations, run ibmcloud sat storage config ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

Get the details of a Satellite storage configuration

ibmcloud sat storage config get --config CONFIG

ibmcloud sat storage config help

Show help

ibmcloud sat storage config help

Examples

Show help

ibmcloud sat storage config help

ibmcloud sat storage config ls

Satellite

List the Satellite storage configurations in your IBM Cloud account.

ibmcloud sat storage config ls [--location LOCATION] [--output OUTPUT] [-q]

Command options

--location
Specify the ID or name of the location that contains the configurations you want to list. To find available locations, run ibmcloud sat location ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List the Satellite storage configurations in your IBM Cloud account

ibmcloud sat storage config ls

ibmcloud sat storage config param help

Show help

ibmcloud sat storage config param help

Examples

Show help

ibmcloud sat storage config param help

ibmcloud sat storage config param set

Satellite

Set the configuration and secret parameters of a Satellite storage configuration.

ibmcloud sat storage config param set --config CONFIG --param PARAM [--param PARAM ...] [--apply] [-f] [-q]

Command options

--apply
Apply the latest Satellite storage configuration version to all assignments of a configuration. To list a configuration's assignments, run ibmcloud sat storage assignment ls --config CONFIG.
--config
Specify the name or ID of the storage configuration. To list Satellite storage configurations, run ibmcloud sat storage config ls.
-f
Force the command to run without user prompts.
-p, --param
Specify a key=value pair for configuration parameters. To see the configuration parameters in a storage template, run ibmcloud sat storage template get.
-q
Do not show the message of the day or update reminders.

Examples

Set the configuration and secret parameters of a Satellite storage configuration

ibmcloud sat storage config param set --config CONFIG --param PARAM

ibmcloud sat storage config patch

Satellite

Apply the latest patch updates to a Satellite storage configuration. Patch updates contain vulnerability remediations and bug fixes within the same major version.

ibmcloud sat storage config patch --config CONFIG [-f] [--include-assignments] [-q]

Aliases: ibmcloud sat upgrade

Command options

--config
Specify the name or ID of a Satellite storage configuration. To list available configurations, run ibmcloud sat storage config ls.
-f
Force the command to run without user prompts.
--include-assignments
Include this option to patch the assignments of the storage configuration to the latest configuration version.
-q
Do not show the message of the day or update reminders.

Examples

Apply the latest patch updates to a Satellite storage configuration

ibmcloud sat storage config patch --config CONFIG

ibmcloud sat storage config rm

Satellite

Remove a Satellite storage configuration.

ibmcloud sat storage config rm --config CONFIG [-f] [--include-assignments] [-q]

Command options

--config
Specify the name or ID of a Satellite storage configuration. To list available configurations, run ibmcloud sat storage config ls.
-f
Force the command to run without user prompts.
--include-assignments
Include this option to remove the storage configuration as well as any associated assignments.
-q
Do not show the message of the day or update reminders.

Examples

Remove a Satellite storage configuration

ibmcloud sat storage config rm --config CONFIG

ibmcloud sat storage help

Show help

ibmcloud sat storage help

Examples

Show help

ibmcloud sat storage help

ibmcloud sat storage template get

Satellite

Get the details of a Satellite storage template

ibmcloud sat storage template get --name NAME --version VERSION [--output OUTPUT] [-q]

Command options

--name
Specify the storage template name. To list available storage templates, run ibmcloud sat storage template ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.
--version
Specify the storage template version. To list available storage templates, run ibmcloud sat storage template ls.

Examples

Get the details of a Satellite storage template

ibmcloud sat storage template get --name NAME --version VERSION

ibmcloud sat storage template help

Show help

ibmcloud sat storage template help

Examples

Show help

ibmcloud sat storage template help

ibmcloud sat storage template ls

Satellite

List the available Satellite storage templates.

ibmcloud sat storage template ls [-q]

Command options

-q
Do not show the message of the day or update reminders.

Examples

List the available Satellite storage templates

ibmcloud sat storage template ls

Subscription commands

View and manage Satellite subscriptions to deploy Kubernetes configuration files to your clusters.

ibmcloud sat subscription create

Satellite

Create a Satellite subscription for clusters. After you create the subscription, the associated Satellite configuration version is automatically deployed to the subscribed clusters.

ibmcloud sat subscription create --config CONFIG --group GROUP [--group GROUP ...] --name NAME [-q] (--auth-required --gitref GITREF --gitref-type TYPE --path PATH --repository REPOSITORY | --version VERSION)

Command options

--auth-required
Provide the authentication secret required to connect to the remote repository. See https://ibm.biz/sat-config-private-repo for details. Strategy: GitOps.
--config
Specify the name of the configuration to use for the subscription. To find available configurations, run ibmcloud sat config ls.
-g, --group
Specify the name or ID of the cluster groups to subscribe to your configuration. To find available cluster groups, run ibmcloud sat group ls.
--gitref
Specify the GitRef to use for the Satellite subscription. Strategy: GitOps.
--gitref-type
Indicate the type of GitRef to use for the Satellite subscription. Strategy: GitOps. Allowed values: branch, commit, tag, release
--name
Enter a name for the subscription.
--path
Provide the path to the repository files or release assets in the remote repository to use for the Satellite subscription. Strategy: GitOps.
-q
Do not show the message of the day or update reminders.
--repository
Specify the URL of the remote repository to use for the subscription. Strategy: GitOps.
--version
Indicate the name or ID of the existing configuration version to use for the subscription. To find versions, run ibmcloud sat config get --config <configuration_name_or_ID>. Strategy: Direct Upload.

Examples

Create a Satellite subscription for clusters

ibmcloud sat subscription create \
  --config CONFIG \
  --group GROUP \
  --name NAME \
  --auth-required \
  --gitref GITREF \
  --gitref-type TYPE \
  --path PATH \
  --repository REPOSITORY

ibmcloud sat subscription get

Satellite

Get detailed information for a Satellite subscription.

ibmcloud sat subscription get --subscription SUBSCRIPTION [--output OUTPUT] [-q]

Command options

--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.
--subscription
Enter the name or ID of a Satellite subscription. To find subscriptions, run ibmcloud sat subscription ls.

Examples

Get detailed information for a Satellite subscription

ibmcloud sat subscription get --subscription SUBSCRIPTION

ibmcloud sat subscription help

Show help

ibmcloud sat subscription help

Examples

Show help

ibmcloud sat subscription help

ibmcloud sat subscription identity help

Show help

ibmcloud sat subscription identity help

Examples

Show help

ibmcloud sat subscription identity help

ibmcloud sat subscription identity set

Satellite

Update the Satellite subscription to use your identity to manage resources.

ibmcloud sat subscription identity set --subscription SUBSCRIPTION [-f] [-q]

Command options

-f
Force the command to run without user prompts.
-q
Do not show the message of the day or update reminders.
--subscription
Specify the name or ID of a Satellite subscription. To list subscriptions, run ibmcloud sat subscription ls.

Examples

Update the Satellite subscription to use your identity to manage resources

ibmcloud sat subscription identity set --subscription SUBSCRIPTION

ibmcloud sat subscription ls

Satellite

List all Satellite subscriptions in your IBM Cloud account.

ibmcloud sat subscription ls [--cluster CLUSTER] [--output OUTPUT] [-q]

Command options

-c, --cluster
Specify the Satellite cluster name or ID. To find registered clusters, run ibmcloud sat cluster ls.
--output
Prints the command output in the provided format. Accepted values: json
-q
Do not show the message of the day or update reminders.

Examples

List all Satellite subscriptions in your IBM Cloud account

ibmcloud sat subscription ls

ibmcloud sat subscription rm

Satellite

Remove a Satellite subscription. The Kubernetes resources are no longer deployed to your clusters.

ibmcloud sat subscription rm --subscription SUBSCRIPTION [-f] [-q]

Command options

-f
Force the command to run without user prompts.
-q
Do not show the message of the day or update reminders.
--subscription
Provide the name or ID of a Satellite subscription. To list subscriptions, run ibmcloud sat subscription ls.

Examples

Remove a Satellite subscription

ibmcloud sat subscription rm --subscription SUBSCRIPTION

ibmcloud sat subscription update

Satellite

Update a Satellite subscription.

ibmcloud sat subscription update --subscription SUBSCRIPTION [-f] [--group GROUP] [--name NAME] [-q] (--auth-required --gitref GITREF --gitref-type TYPE --path PATH --repository REPOSITORY | --version VERSION)

Command options

--auth-required
Provide the authentication secret required to connect to the remote repository. Strategy: GitOps.
-f
Force the command to run without user prompts.
-g, --group
Specify the new cluster groups to subscribe to your configuration.
--gitref
Specify the GitRef to use for the Satellite subscription. Strategy: GitOps.
--gitref-type
Indicate the type of GitRef to use for this Satellite subscription. Strategy: GitOps. Allowed values: branch, commit, tag, release
--name
Provide a new name of the Satellite subscription.
--path
Indicate the path to the repository files or release assets in the remote repository to use for the Satellite subscription. Strategy: GitOps.
-q
Do not show the message of the day or update reminders.
--repository
Provide the URL of the remote repository to use for the Satellite subscription. Strategy: GitOps.
--subscription
Specify the name or ID of a Satellite subscription. To list subscriptions, run ibmcloud sat subscription ls.
--version
Indicate the existing configuration version to use for the Satellite subscription. Strategy: Direct Upload.

Examples

Update a Satellite subscription

ibmcloud sat subscription update \
  --subscription SUBSCRIPTION \
  --auth-required \
  --gitref GITREF \
  --gitref-type TYPE \
  --path PATH \
  --repository REPOSITORY